Solutions

Automatically Generate the Register of Information

Manual spreadsheets are a thing of the past — with Leno TPRM, you create and maintain a complete, audit-proof register of information automatically and in full compliance with DORA.

Get a demo

Register Information at a Click

No Excel sheets. No gaps. A real-time register of information for single entities and entire groups.

High manual effort

  • Registers are maintained and updated manually, often in Excel
  • Changes must be updated several times
  • High Costs for Checks and Reports

Lack of timeliness

  • Changes to services and contracts are not implemented promptly
  • Registers do not reflect the current database
  • Discrepancies between actual and target conditions

Inconsistent data

  • Different versions of the same data
  • Contradictions between the various reports
  • Difficult traceability for supervision and audit
Credit card mockups

How Leno Automates Outsourcing and Information Registries

Leno enables financial companies to automatically create and maintain outsourcing and information registers — directly from the underlying processes.

Central database

  • Uniform recording of all outsourcing and ICT services
  • Common Data Source for Information Registers and Outsourcing Registers
  • Avoiding redundant data maintenance

Automatic update

  • Changes to service providers, risks or assessments are automatically adopted
  • Registers are always up to date and consistent
  • No separate maintenance required before testing

Reporting at the Push of a Button

  • Quick provision of registers in the required format
  • Register content structured in accordance with regulatory requirements
  • Traceability of data sets
Credit card mockups

Why an automatic register is better than manual solutions

Many institutions continue to rely on Excel or isolated tools to maintain their registers. As complexity increases, these approaches quickly reach their limits.

Features
Andere Tools
Compliance
Generische Funktionen für DORA, MaRisk & EBA-Leitlinien
Vollständige Compliance mit automatisierten Informationsregsiter
Flexibilität
Statisch oder nur mit Programmierung
Konfigurierbar ohne Code
Modul-Integration
Getrennte Einzellösungen
Alles in einer Plattform, nahtlos verknüpft
Startgeschwindigkeit
Lange Implementierung
Sofort einsatzbereit mit Templates
KI-Funktionen
Oft nicht vorhanden
Oft nicht vorhanden

Other Tools

High maintenance costs, prone to errors, low timeliness and high audit stress
Automatic maintenance from operational processes, uniform and consistent data - audit-ready at any time.
Test for free
Timeliness of Registers
Andere
Outsourcing and information registers are often updated on a case-by-case basis or in advance of audits.
Registers are updated continuously and automatically from the underlying workflows.
Data consistency and quality
Andere
There are often several versions of the same register in different subject areas.
All registers are based on a central data source. Outsourcing, ICT services, third parties and risks are recorded once and reused consistently.
Regulatory structure and completeness
Andere
The structure of the registers is often based on existing Excel templates, not on current regulatory requirements.
The Outsourcing and Information Register has a regulatory structure and is based on the requirements of DORA, EBA guidelines and MaRisk.
Ability to audit and provide information
Andere
High manual effort required to prepare register information for checks and queries.
Registers are audit-proof at any time and can be provided without additional effort.
Operational expenses
Andere
High maintenance costs, media breaks and manual coordination between specialist areas.
Automated maintenance significantly reduces manual effort and the risk of errors.
Flexibilität
Andere Tools sind statisch oder nur mit Programmierung
Leno ist konfigurierbar ohne Code
Modul-Integration
Andere Tools bilden getrennte Einzellösungen
Leno ist eine All-in-One-Plattform, nahtlos verknüpft
Startgeschwindigkeit
Andere Tools erfodern lange Implementierung
Leno ist sofort einsatzbereit mit Templates
KI-Funktionen
In anderen Tools oft nicht vorhanden
Leno verfügt über integrierte KI für Analyse & Automatisierung

Important questions about the Automated Outsourcing and Information Register

Find out which requirements apply, which information must be collected and how Leno helps financial institutions to continuously maintain, update and provide the registers in an audit-proof manner.
What is an outsourcing register?

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

An outsourcing register or vendor repository is a structured overview of all outsourcing arrangements of a financial institution. It ensures transparency towards supervisory authorities and auditors and provides a reliable basis for identifying and managing concentration risks, including at EU level.

What is the information register under DORA?

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

The information register is a DORA-mandated register that contains detailed information on ICT services, ICT third-party providers, and critical functions across 15 tables. It allows supervisory authorities to gain a quick, consistent overview of an institution's ICT landscape, as well as concentration risks and dependencies at the EU level.

How can Leno generate registers automatically and in real time?

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Leno generates outsourcing and information registers automatically based on a central, integrated data source. Information on outsourcing, ICT services, third parties, risks, and contracts is recorded once in a structured manner and then transferred in real time to the respective registers. Changes—such as updates to service providers, services, risk classifications, or approvals—are immediately applied and are visible in the outsourcing and information registers without manual maintenance.

Wie unterstützt Leno bei Prüfungen und Auskunftsersuchen?

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Leno provides the register at any time in an audit-proof, consistent, and traceable manner as of a given date. Data states, changes, and histories can be made available at the push of a button - without manual preparation.

When must an information register be created?

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Under DORA, financial institutions are required to maintain an information register as soon as they enter into contractual arrangements for the use of ICT services with third-party providers. This register must be kept up to date on an ongoing basis and submitted to the competent supervisory authorities at least once a year or made available upon request.

Which information must be included in the information register?

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

The information register must include detailed information on ICT service providers and their respective contracts, including service identification, contract details, supported functions, classification as critical or non-critical, information on risks, and any subcontractors.

What are the differences between the outsourcing register and the DORA information register?

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

The DORA information register goes beyond traditional outsourcing registers, as it must additionally include structured data on ICT services, third parties, and critical functions—often in predefined tables (15-table model)—and is specifically designed for use by supervisory authorities and ESAs.

Does the information register need to be reported to the supervisory authority?

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Yes. Financial institutions must provide the register in full to the competent supervisory authority upon request and, in many jurisdictions, submit it annually. This includes information on new contracts, categories of service providers, and the type of ICT services provided.

Is the information register only relevant internally, or is it also used externally?

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

The register serves internal ICT risk management but is also used externally by supervisory authorities to monitor systemic risks and support the identification of critical ICT third-party providers at the EU level.

Up to which level must ICT third-party providers be listed in the information register?

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

This depends on the criticality of the supported function. If an ICT service does not support a critical or important function of the financial institution, generally only the ICT third-party provider in a direct contractual relationship with the financial institution (Tier 1) needs to be recorded. Subcontractors at downstream levels do not need to be listed in this case.

Do intra-group ICT services need to be recorded in the information register?

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Yes, intra-group ICT services must also be recorded in the information register. DORA generally does not distinguish between external and intra-group ICT providers. What matters is that an ICT service is provided to a financial institution and may impact its ICT resilience. An exception exists for the use of intra-group ICT providers, where additional information may be required, particularly to map ICT service chains. The relevant requirements are outlined in Commission Implementing Regulation (EU) 2024/2956, Annex I, Part 2, including the specifications for completing Template B_05.02.

Get to know Leno

Book a demo
Book a meeting today to discover Leno.